Noticias de ultima
  • 12.00 Tech innovator Randi Zuckerberg to Headline Debut AI Academy at SBC Summit 2025
  • 12.00 GGL Launches First Quarterly Report on Cross-Border Gambling and Betting
  • 12.00 GAT CDMX 2025: Cutting-edge Sessions And Training To Transform The Gaming Industry In Latin America
  • 12.00 India’s Top Real Money Gaming Platforms Suspend Paid Following New Online Gaming Law
  • 12.00 Philippines: Hann Holdings Postpones IPO Amid Market Uncertainty
  • 12.00 Imagine Live Joins BlueOcean Gaming’s GameHub Aggregation Platform
  • 12.00 New Zealand Issues 15 Fresh Online Casino Licences: What’s Next?
  • 12.00 Presque Isle Downs & Casino Secures 5 Years License Renewal Amid Financial Scrutiny
  • 12.00 NOVOMATIC and Mecca Bingo Elevate UK Gaming Experience with Next Gen Installations
  • 12.00 Brazil: Illegal betting threatens tax revenue, causes losses of R$ 10.8 billion per year
Sportsbook

Massachusetts imposes Data Privacy Rules on Sports Betting Operators: What You Need to Know

Friday 15 de September 2023 / 12:00

2 minutos de lectura

(Massachusetts).- The Massachusetts Gaming Commission recently approved new Sports Wagering Data Privacy Rules that will likely require companies to implement new policies to protect their customer’s personal information.

Massachusetts imposes Data Privacy Rules on Sports Betting Operators: What You Need to Know

The rules, which became effective on September 1, 2023, share several similarities with the California Privacy Rights Act (CPRA) and Colorado Privacy Act (CPA). Still, they also include a few unique directives that must be considered.

Here is what do you need to know:

Broad definitions

  • The definition of “personally identifiable information” is broad and tracks CPRA and other state laws, including information which is “reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular patron, individual or household.”
  • The definition of “confidential information” is very broad, and includes things like amount credited to, debited from, withdrawn from, or present in any particular sports wagering account; the amount of money wagered by a particular patron on any event or series of events; the unique patron ID or username and authentication credentials that identify the patron; the identities of particular sporting events on which the patron is wagering or has wagered, or the location from which the patron is wagering, has wagered, or has accessed their sports wagering account.

Privacy notice

  • Required disclosure on all information collected, purpose, sharing and security.
  • There needs to be active agreement to the notice before collection, as well as agreement to any material updates (but this is different from secondary uses, which require consent as opposed to “agreement.”)

Data minimization; consent and personalization

  • Data minimization and retention limitation. A Sports Wagering Operator shall only use confidential information and personally identifiable information as necessary to operate the facility or platform or to comply with the law and other specific purposes, like security.
  • Consent is necessary for any secondary uses. It can be withdrawn at any time without any dark patterns interfering with this.
  • Consent needs to be clear and conspicuous and separate from any terms of use.
  • You may not promote or target based on things like: (1) income, debt, net worth, credit history, or status as beneficiary of governmental programs; medical status or conditions; occupation; (2) period of dormancy or non-use of a Sports Wagering Platform; (3) the wagers made or promotional offers accepted by other patrons with a known or predicted social connection to the patron; (4) the communications of the patron with any third party other than the operator; (5) automated decision making; (6) usage of cooling off or play management options.
  • Requirement to collect and aggregate patrons’ confidential information and personally identifiable information to analyze patron behavior for the purposes of identifying and developing programs and interventions to promote responsible gaming and support problem gamblers, and to monitor and deter sports wagering in violation.

Data sharing

  • Sharing only as necessary and requiring the recipient to maintain in confidence and only use for the purpose (aka: data sharing agreements required).
  • For sharing which is necessary for the service, you need a data sharing agreement with specific provisions including information security and incident response.
  • Required use of encryption and Multi-Factor Authentication (MFA).

Patron rights

  • Including a description of the processing: a copy of the information held, updates to the information, restriction on use and deletion.
  • Specific requirements around responding to requests and deletion of the information.

Required data program

  • A Sports Wagering Operator shall develop, implement and maintain comprehensive administrative, technical and physical data privacy and security policies appropriate to the size and scope of business and addressing confidentiality, security, secure disposal, employee training on data privacy, restrictions on access, monitoring of systems, cybersecurity insurance, incident response, and periodic audits.
  • Required compliance with all applicable state and federal data security requirements including: M.G.L. c. 93A, M.G.L. c. 93H, 940 CMR 3.00, 940 CMR 6.00 and 201 CMR 17.00.

Data breach notification

  • Required notification of the Commission within 5 days of discovery of a suspected data breach involving CI or PII.
  • Required submission of completed investigation report and remediation plan (if applicable).
  • Submission of a report from a qualified third-party forensic examiner (if required).
  • Compliance with all applicable data breach laws.

Categoría:Sportsbook

Tags: Sin tags

País: United States

Región: North America

Event

Peru Gaming Show 2025

18 de June 2025

Facephi presented its digital identity verification solutions for the online gaming sector in Peru at PGS 2025

(Lima, SoloAzar Exclusive).- Facephi is consolidating its position as a strategic partner for responsible online gaming in Peru, presenting advanced identity verification, fraud prevention, and regulatory compliance solutions at PGS 2025, adapted to an increasingly digital and demanding ecosystem. In this interview, Bruno Rafael Rivadeneyra Sánchez, the firm's Identity Solutions Senior Manager, explores how its technology is redefining gaming security standards, with a preventative, seamless, and 100% regional approach.

Friday 18 Jul 2025 / 12:00

From PGS 2025, Win Systems Redoubles its Commitment to Peru: Innovation, Proximity, and Regional Expansion

(Lima, SoloAzar Exclusive).- In a revealing interview, Galy Olazo, Country Manager of Win Systems in Peru, analyzes the company's strategic role in one of the most thriving markets in the region. Its participation in the PGS 2025 trade show not only left its mark with its technological advances, such as the new Gold Club Colors electronic roulette wheels and the WIGOS management system, but also reaffirmed its commitment to the transformation of the sector and its consolidation in Latin America.

Tuesday 15 Jul 2025 / 12:00

Key debate during PGS 2025: Enforcement: Process to ensure compliance (laws, norms, rules)

(Lima, SoloAzar Exclusive).- During the 2025 edition of the Peru Gaming Show, the conference ‘Enforcement: Process to ensure compliance (laws, norms, rules)’ took place, with an international panel of professionals who debated about the current challenges to combat illegal gaming and guarantee the application of the laws in the sector, both in Peru and in the Latam region.

Monday 14 Jul 2025 / 12:00

SUSCRIBIRSE

Para suscribirse a nuestro newsletter, complete sus datos

Reciba todo el contenido más reciente en su correo electrónico varias veces al mes.

PODCAST

MÁS CONTENIDO RELACIONADO